CVE-2023-38180
KEV High · CVSS 7.5- CVSS
- 7.5
- nvd
- EPSS
- 14.8%
- 96th pct
- KEV
- Listed
- 2023-08-09
- Class
- oss containerizable
- NVD-CWE-noinfo, CWE-400
Description
.NET and Visual Studio Denial of Service Vulnerability
Affected packages
| Bitnami | aspnet-core | 2.1.0 → 2.1.40 |
| Bitnami | dotnet | 6.0.0 → 6.0.21 |
| Bitnami | dotnet | 7.0.0 → 7.0.10 |
| Bitnami | dotnet-sdk | 6.0.0 → 6.0.21 |
| Bitnami | dotnet-sdk | 7.0.0 → 7.0.10 |
| NuGet | Microsoft.AspNetCore.App.Runtime.win-arm64 | 6.0.0 → 6.0.21 |
| NuGet | Microsoft.AspNetCore.App.Runtime.win-arm64 | 7.0.0 → 7.0.10 |
| NuGet | Microsoft.AspNetCore.App.Runtime.win-x64 | 6.0.0 → 6.0.21 |
| NuGet | Microsoft.AspNetCore.App.Runtime.win-x64 | 7.0.0 → 7.0.10 |
| NuGet | Microsoft.AspNetCore.App.Runtime.win-x86 | 6.0.0 → 6.0.21 |
| NuGet | Microsoft.AspNetCore.App.Runtime.win-x86 | 7.0.0 → 7.0.10 |
| NuGet | Microsoft.AspNetCore.Server.Kestrel.Transport.Libuv | 0 → 2.1.40 |
| NuGet | Microsoft.AspNetCore.Server.Kestrel.Transport.Libuv | 6.0.0 → 6.0.21 |
| NuGet | Microsoft.AspNetCore.Server.Kestrel.Transport.Sockets | 0 → 2.1.40 |
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-38180
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CL2L4WE5QRT7WEXANYXSKSU43APC5N2V/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NWVZFKTLNMNKPZ755EMRYIA6GHFOWGKY/
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-38180
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-38180
Status: profiled · ingested 2026-08-10T18:00:50.000Z